Active Directory trace log

The attachments is the trace log about I reset password from IDM sync to
Active Directory.
I am sure it success about reset password at line 48.
But, why dose the driver publish the modify password event from AD to
IDM after subscriber success?(line 53 - line 120)
Even, the driver publish the user add event from AD to IDM!!(line 121 -
line 296) I can't understand about this data flow...
anybody can help me?
thank you very much.

Re: Active Directory trace log

Without looking at the trace (I know, what kind of person am I?) the
reason that events are picked up on the publisher channel depends on the
type of event.

1. The application (microsoft active directory (MAD)) has no way to
determine if an event came from the driver or from a regular
administrator. As a result, all regular (non-password) events that match
the driver filter on the Publisher channel are picked up, looped back, and
then eventually dealt-with by the IDM engine which then does NOT loopback
(unless you configure it to) because unlike MAD it can tell that an event
came from itself to avoid sending it back to the application.

2. Passwords are basically the same; password changes hit the filter and
the filter has no idea at all what sent it, and as a result the filter
sends the password change event back to the engine.

Neither of these usually matter much in a negative way. The engine is
smart enough to optimize out non-changes, and even if it does not nothing
will usually change when the engine gets back the same value that it sent
to the application.

Good luck.

